fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
//go:build windows
|
||||
|
||||
package safeio
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"path/filepath"
|
||||
|
||||
"golang.org/x/sys/windows"
|
||||
)
|
||||
|
||||
func preflightPrivateDirectory(path string) (bool, error) {
|
||||
parents, target, err := openCanonicalWindowsParent(path)
|
||||
if err != nil {
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
defer parents.Close()
|
||||
handle, err := openWindowsComponent(filepath.Join(parents.directory, target), true)
|
||||
if err != nil {
|
||||
if errors.Is(err, windows.ERROR_FILE_NOT_FOUND) {
|
||||
writableParent, accessErr := openWindowsComponentWithAccess(
|
||||
parents.directory,
|
||||
true,
|
||||
windows.FILE_APPEND_DATA, // FILE_ADD_SUBDIRECTORY for a directory handle
|
||||
)
|
||||
if accessErr != nil {
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
_ = windows.CloseHandle(writableParent)
|
||||
return false, nil
|
||||
}
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
defer windows.CloseHandle(handle)
|
||||
if err := validateOwnerOnlyDACL(handle); err != nil {
|
||||
return false, ErrUnsafeFile
|
||||
}
|
||||
return true, nil
|
||||
}
|
||||
Reference in New Issue
Block a user